Quotation
Hooking Up The Big Brother Machine... And Fighting It
Hooking Up The Big Brother Machine... And Fighting It: Via EFF.org Updates.
Here's a movie pitch: One lone telecommunications technician, going about his ordinary daily work in San Francisco, begins to realize things aren't quite what they seem. There's a "secret room" downstairs, and ordinary employees aren't allowed to enter it. Coworkers — almost casually! — remark that a government spy agency is involved, that similar facilities are being built across the country, that some of them are stamped with the government's ominous eye-and-pyramid "Total Information Awareness" logo.
Soon, the plot thickens. Mundane technical procedures produce startling revelations. He stumbles on a document that suggests the room contains a supercomputer designed to data-mine phone calls and Internet traffic. And, indeed, he soon realizes that the room is sucking up copies of electronic communications from millions of random Americans.
All this in the early 2000s, when "the political atmosphere in the country after 9/11 had a witchhunt feel to it, and even modest criticism of the administration was getting painted as disloyalty or worse."
What happens to our hero when he finally decides to go public? [ Read more ... ]
How Privacy Vanishes Online
How Privacy Vanishes Online: Via NYT > Privacy.
Using innocuous bits of data from Web sites like Facebook and Twitter, researchers gleaned people’s names, ages and even Social Security numbers.
Yet people often dole out all kinds of personal information on the Internet that allows such identifying data to be deduced. Services like Facebook, Twitter and Flickr are oceans of personal minutiae — birthday greetings sent and received, school and work gossip, photos of family vacations, and movies watched.
Computer scientists and policy experts say that such seemingly innocuous bits of self-revelation can increasingly be collected and reassembled by computers to help create a picture of a person’s identity, sometimes down to the Social Security number.
“Technology has rendered the conventional definition of personally identifiable information obsolete,” said Maneesha Mithal, associate director of the Federal Trade Commission’s privacy division. “You can find out who an individual is without it.” [ Read more ... ]
Undercover Feds on Social Networking Sites Raise Questions
Undercover Feds on Social Networking Sites Raise Questions: Via Threat Level.
The next time someone ties to “friend” you on Facebook, it may turn out to be an undercover fed looking to examine your private messages and photos, or surveil your friends and family, according to an internal Justice Department document obtained by the Electronic Frontier Foundation.
The 33-page document shows that law enforcement agents from local police to the FBI and Secret Service have been logging on to MySpace and other sites undercover to communicate with suspects, read private postings and view photos and videos that are restricted to a user’s friends, according to the Associated Press.
The document also describes techniques for verifying alibis — such as checking messages posted by a suspect on Twitter disclosing his whereabouts at the time a crime was committed — and uncovering information that might point to illegal activity, such as photos depicting a suspect with expensive jewelry, a new car or even a weapon.
The document says that evidence from social networking sites can: [ Read more ... ]
Obama threatens to veto greater intelligence oversight
Obama threatens to veto greater intelligence oversight: Via Salon: Glenn Greenwald.
(updated below)
One of the principal weapons used by the Bush administration to engage in illegal surveillance activities -- from torture to warrantless eavesdropping -- was its refusal to brief the full Congressional Intelligence Committees about its activities. Instead, at best, it would confine its briefings to the so-called "Gang of Eight" -- comprised of 8 top-ranking members of the House and Senate -- who were impeded by law and other constraints from taking any action even if they learned of blatantly criminal acts.
This was a sham process: it allowed the administration to claim that it "briefed" select Congressional leaders on illegal conduct, but did so in a way that ensured there could be no meaningful action or oversight, because those individuals were barred from taking notes or even consulting their staff and, worse, because the full Intelligence Committees were kept in the dark and thus could do nothing even in the face of clear abuses. The process even allowed the members who were briefed to claim they were powerless to stop illegal programs. That extremely restrictive process also ensures irresolvable disputes over what was actually said during those briefings, as illustrated by recent controversies over what Nancy Pelosi and other leading Democrats were told about Bush's torture and eavesdropping programs. Here's how Richard Clarke explained it in July, 2009, on The Rachel Maddow Show: [ Read more ... ]
EFF Asks Illinois Appellate Court to Block Unmasking of Anonymous Online Critic
EFF Asks Illinois Appellate Court to Block Unmasking of Anonymous Online Critic: Via EFF.org Updates.
Chicago - The Electronic Frontier Foundation (EFF) and the Media Freedom and Information Access Practicum (MFIA) at Yale Law School filed a friend-of-the-court brief today urging the Illinois Court of Appeals to block the unmasking of an anonymous online critic of a local political candidate.
The critic, commenting on a story on the website of a suburban Chicago newspaper called the Daily Herald, engaged in a heated debate with other commenters. One turned out to be the son of the village trustee candidate in Buffalo Grove, Illinois, who was discussed in the article. The candidate, Lisa Stone, who eventually won her race, asked a state court to order the newspaper to release the critic's name and address without appropriately showing that the statements directed towards her son were defamatory or otherwise illegal. Stone indicated that she may choose to subsequently file a lawsuit once she determines the critic's identity through the pre-complaint procedure.
"Because of the enormous potential for abuse, the First Amendment requires litigants to demonstrate that they have a legitimate case before they can use the courts to unmask anonymous online critics," said EFF Senior Staff Attorney Matt Zimmerman. "Insults are not enough, especially when the conversation takes place in the context of a political campaign." [ Read more ... ]
Investigators: Businesses buying your credit card number
Investigators: Businesses buying your credit card number: Via NorthWest Cable News.
$10 here. $15 there.
By putting little charges on your credit card some companies are making tens of millions of dollars a year. These are businesses that you never gave your credit card number to.
Some consumer groups call it fraud, but it may be perfectly legal.
Christie Frison-Thornton, of Rainier, spotted a $19.95 charge just a few weeks ago. A company called "Privacy Matters" billed her credit card.
"I thought what the heck is this? Cause I really did not have a clue," said Frison-Thornton. [ Read more ... ]
Global Internet Freedom and the U.S. Government
Global Internet Freedom and the U.S. Government: Via Freedom to Tinker.
Over the past two weeks I've testified in both the Senate and the House on how the U.S. should advance "Internet freedom." I submitted written testimony for both hearings which can be downloaded in PDF form here and here. Full transcripts will become available eventually but meanwhile you can click here to watch the Senate video and here to watch the House video. In both hearings I advocated a combination of corporate responsibility through the Global Network Initiative backed up by appropriate legislation given that some companies seem reluctant to hold themselves accountable voluntarily; revision of export controls and sanctions; and finally, funding and support for tools, and technologies and activism platforms that will counter-act suppression of online speech.
[ Read more ... ]
The dark side of DNA
The dark side of DNA: Via The Globe and Mail.
The only real evidence in a first-degree murder charge against Mr. Turner, the golden sheen of DNA appeared certain to become a silver bullet in the hands of the Crown.
"I told my lawyer, Jerome Kennedy, that there was no way in the world it was true," Mr. Turner recalled in an interview. "He believed me. He said that I was too stupid to commit that crime and leave no evidence."
A lucky hunch by Mr. Kennedy - now Newfoundland's Minister of Health - saved Mr. Turner from a life behind bars. He sought the name and DNA profile of every technician who had worked at the RCMP lab. It turned out that the technician who had tested the ring had also been working on the victim's fingernails a few inches away, creating a strong possibility of contamination.
The technician conceded at Mr. Turner's 2001 trial that she had also contaminated evidence in two previous cases. [ Read more ... ]
Telling Friends Where You Are (or Not) - NYT
Telling Friends Where You Are (or Not): Via NYTimes.com .
Mobile services like Loopt and Google’s Latitude have promoted the notion of constantly beaming your location to a map that is visible to a network of friends — an idea that is not for everybody.
But now there is a different approach, one that is being popularized by Foursquare.
After firing up the Foursquare application on their phones, users see a list of nearby bars, restaurants and other places, select their location and “check in,” sending an alert to friends using the service.
This model, which may be more attractive than tracking because it gives people more choice in revealing their locations, is gathering speed in the Internet industry. Yelp, the popular site that compiles reviews of restaurants and other businesses, recently added a check-in feature to its cellphone application. And Facebook is expected to take a similar approach when it introduces location features to its 400 million users in coming months. [ Read more ... ]
Advertising - Instant Ads Set the Pace on the Web
Advertising - Instant Ads Set the Pace on the Web: Via NYTimes.com .
Now, companies like Google, Yahoo and Microsoft let advertisers buy ads in the milliseconds between the time someone enters a site’s Web address and the moment the page appears. The technology, called real-time bidding, allows advertisers to examine site visitors one by one and bid to serve them ads almost instantly.
For example, say a man just searched for golf clubs on eBay (which has been testing a system from a company called AppNexus for more than a year). EBay can essentially follow that person’s activities in real time, deciding when and where to show him near-personalized ads for golf clubs throughout the Web.
If eBay finds out that he bought a driver at another site, it can update the ad immediately to start showing him tees, golf balls or a package vacation to St. Andrew’s, Scotland, often called the home of golf. If a woman was shopping, eBay could change the ad’s color or presentation. [ Read more ... ]
TJX Hacking Conspirator Gets 4 Years
TJX Hacking Conspirator Gets 4 Years: Via Threat Level.
Humza Zaman, a co-conspirator in the hack of TJX and other companies, was sentenced Thursday in Boston to 46 months in prison and fined $75,000 for his role in the conspiracy. The sentence matches what prosecutors were seeking.
Zaman, a 33-year-old former network security manager at Barclays Bank, was charged with laundering between $600,000 and $800,000 for hacker Albert Gonzalez, who is currently awaiting sentencing on charges that he and others hacked into TJX, Office Max, Heartland Payment Systems and numerous other companies to steal data on more than 100 million credit and debit card accounts.
Zaman pleaded guilty in April to one count of conspiracy. His sentence includes three years of supervised release with the condition that Zaman must disclose his conviction to any future employer. Upon release, Zaman will not be barred from using computers. [ Read more ... ]
Feds: TSA Worker Tried to Sabotage Terror Database
Feds: TSA Worker Tried to Sabotage Terror Database: Via Threat Level.
A former Transportation Security Administration contractor is being charged in Colorado for allegedly injecting malicious code into a government network used for screening airport security workers and others.
The malicious code, a logic bomb installed last October, was designed to cause damage and disrupt data on servers on an undisclosed date but was caught by other workers before it delivered its payload.
Douglas James Duchak, 46, had worked as a data analyst at the TSA’s Colorado Springs Operations Center, or CSOC, since 2004. The CSOC is used to vet people who have “access to sensitive information and secure areas of the nation’s transportation network,” according to the indictment. A source involved in the case said this involved screening of both passengers and workers at airports and other transportation facilities.
He pleaded not guilty in a Denver federal court on Wednesday and was released on a $25,000 unsecured bond. The indictment did not say whether the malware was crafted to erase or alter data, or simply disable servers.
The CSOC network stores updated information from the government’s terrorist watchlist as well as criminal histories from the U.S. Marshal’s Service Warrant Information Network. [ Read more ... ]
Zeus botnet dealt a blow as ISP Troyak knocked out
Zeus botnet dealt a blow as ISP Troyak knocked out: Via Computerworld Cybercrime/Hacking News.
Internet service providers linked to the notorious Zeus botnet have been taken down, knocking out a third of the command-and-control servers that run the network of hacked machines.
Two ISPs, named Troyak and Group 3, were home to 90 of the 249 known Zeus command-and-control servers. Zeus Tracker, a Web site that tracks the botnet, noticed the steep drop in servers on Wednesday morning.
The Troyak network was itself an upstream provider to six networks, known to host a large number of cybercrime servers, including Web sites used in drive-by attacks and phishing sites, according to Kevin Stevens, a researcher with SecureWorks. "There's lots of Zeus and Fragus exploit kit [sites]," he said. Whoever was behind the takedown "just decided to knock out a large area of cybercirme, and this was probably one of the easiest ways to do it." [ Read more ... ]
European Parliament Rips Global IP Accord (ACTA)
European Parliament Rips Global IP Accord: Via Threat Level.
The European Parliament delivered a political blow to Hollywood and the Obama administration, voting Wednesday 663 to 13 in opposition to a proposed and secret intellectual property agreement being negotiated by the European Union, United States and a handful of others.
Wednesday’s developments concerning the Anti-Counterfeiting and Trade Agreement are substantial because the European Union’s 27 countries vastly outnumber the remaining countries negotiating the deal. They are Australia, Canada, Japan, South Korea, Mexico, Morocco, New Zealand, Singapore, Switzerland and the United States. Ambassador Ron Kirk, the top U.S. trade official, is spearheading the deal that began being crafted under the George W. Bush administration.
Kirk’s office declined comment.
To be sure, there is a dispute and heavy confusion concerning whether internet service providers under ACTA would be forced to punish customers deemed copyright scofflaws by reducing or eliminating service, according to a string of leaked documents. So Parliament members also agreed Wednesday to oppose the measure if it contains so-called “three strikes” or “graduated response” policies — regardless of whether that’s now in the text.
And because of the text’s secrecy, Parliament on Wednesday also demanded (.pdf) that the private agreement still under negotiation be publicly released. [ Read more ... ]
Hackers exploit latest IE zero-day with drive-by attacks
Hackers exploit latest IE zero-day with drive-by attacks: Via Computerworld Cybercrime/Hacking News.
Hackers are exploiting the just-disclosed unpatched bug in Internet Explorer (IE) to launch drive-by attacks from malicious Web sites, security researchers said today.
"This attack appears to be rather targeted at the moment, but as with other unpatched vulnerabilities in the past, this has the potential to explode now that the word is getting out," said Craig Schmugar, a threat researcher at McAfee, in a blog post today.
Attacks are launched from Web sites in a classic drive-by fashion, said Schmugar and others. "Visiting the page is enough to get infected," Schmugar said.
Symantec also confirmed that it has spotted in-the-wild attacks exploiting the critical vulnerability in IE6 and IE7 that Microsoft acknowledged yesterday. "We're still seeing just limited attacks," said Ben Greenbaum, a senior research manager on Symantec's security response team. "The exploit is carried out simply by visiting a Web page hosting the vulnerability. When the browser opens the page, the exploit causes the user's computer to download and execute another piece of malware." [ Read more ... ]
Mobile that allows bosses to snoop on staff developed
Mobile that allows bosses to snoop on staff developed: Via BBC News.
Researchers have produced a mobile phone that could be a boon for prying bosses wanting to keep tabs on the movements of their staff.
Japanese phone giant KDDI Corporation has developed technology that tracks even the tiniest movement of the user and beams the information back to HQ.
It works by analysing the movement of accelerometers, found in many handsets.
Activities such as walking, climbing stairs or even cleaning can be identified, the researchers say.
The company plans to sell the service to clients such as managers, foremen and employment agencies.
"Technically, I think this is an incredibly important innovation," says Philip Sugai, director of the mobile consumer lab at the International University of Japan. [ Read more ... ]
The majestic petulance of John Roberts
The majestic petulance of John Roberts: Via Salon: Glenn Greenwald.
The petulance and sense of self-importance on display here is quite something to behold:
[ Read more ... ]U.S. Supreme Court Chief Justice John Roberts said Tuesday the scene at President Obama's State of the Union address was "very troubling" . . . . Obama chided the court, with the justices seated before him in their black robes, for its decision on a campaign finance case. . . . Responding to a University of Alabama law student's question, Roberts said anyone was free to criticize the court, and some have an obligation to do so because of their positions.
"So I have no problems with that," he said. "On the other hand, there is the issue of the setting, the circumstances and the decorum.
"The image of having the members of one branch of government standing up, literally surrounding the Supreme Court, cheering and hollering while the court -- according the requirements of protocol -- has to sit there expressionless, I think is very troubling."
The NYPD. Is Watching Certain People ( NYT Op-Ed Columnist )
The N.Y.P.D. Is Watching Certain People: Via NYTimes.com .
From 2004 through 2009, in a policy that has gotten completely out of control, New York City police officers stopped people on the street and checked them out nearly three million times, frisking and otherwise humiliating many of them.
Upward of 90 percent of the people stopped are completely innocent of any wrongdoing. And yet the New York Police Department is compounding this intolerable indignity by compiling an enormous and permanent computerized database of these encounters between innocent New Yorkers and the police.
Not only are most of the people innocent, but a vast majority are either black or Hispanic. There is no defense for this policy. It’s a gruesome, racist practice that should offend all New Yorkers, and it should cease. [ Read more ... ]
Worker ID Card at Center of Immigration Plan - WSJ.com
Worker ID Card at Center of Immigration Plan: Via Wall Street Journal.
Lawmakers working to craft a new comprehensive immigration bill have settled on a way to prevent employers from hiring illegal immigrants: a national biometric identification card all American workers would eventually be required to obtain.
Under the potentially controversial plan still taking shape in the Senate, all legal U.S. workers, including citizens and immigrants, would be issued an ID card with embedded information, such as fingerprints, to tie the card to the worker.
The ID card plan is one of several steps advocates of an immigration overhaul are taking to address concerns that have defeated similar bills in the past.
The uphill effort to pass a bill is being led by Sens. Chuck Schumer (D., N.Y.) and Lindsey Graham (R., S.C.), who plan to meet with President Barack Obama as soon as this week to update him on their work. An administration official said the White House had no position on the biometric card. [ Read more ... ]
Feds Move to Break Voting-Machine Monopoly
Feds Move to Break Voting-Machine Monopoly: Via Threat Level.
Citing anti-competitive concerns, the Justice Department sued Election Systems & Software in order to force the company to divest itself of the voting machine assets it obtained from Premier Election Solutions last year.
The department’s Antitrust Division, along with nine state attorneys general, filed the civil antitrust lawsuit (.pdf) in U.S. District Court in Washington, D.C., charging that the acquisition threatened competition. The department proposed a settlement that, if accepted, would dissolve the merger and force ES&S to sell its Premier business to a buyer approved by the Justice Department.
“The proposed settlement (.pdf) will restore competition, provide a greater range of choices and create incentives to provide secure, accurate and reliable voting equipment systems now and in the future,” said Molly S. Boast, deputy assistant attorney general for the Antitrust Division in a statement. [ Read more ... ]
The Cell Phone Network: Law Enforcement's Surveillance Dream
The Cell Phone Network: Law Enforcement's Surveillance Dream: Via Blog of Rights: Official Blog of the American Civil Liberties Union.
Yesterday, WNYC's On the Media (OTM) profiled our cell phone tracking case. In this case, the ACLU, Center for Democracy and Technology and the Electronic Frontier Foundation (EFF) asked the court to require that the government at least show probable cause before it can ask a wireless provider to fork over information about your whereabouts using GPS or cell tower tracking via your cell phone. We won in the district court (PDF); the government appealed that decision to the 3rd Circuit. [ Read more ... ]
Security Pros Question Deployment of Smart Meters
Security Pros Question Deployment of Smart Meters: Via Threat Level.
The country’s swift deployment of smart-grid technology has security professionals concerned that utilities and smart-meter vendors are repeating the mistakes made in the rollout of the public internet, when security became a priority only after malicious attacks had reached mass levels.
But when it comes to the power grid, the costs of remote hack attacks are potentially more dramatic.
“The cost factor here is what’s turned on its head. We lose control of our grid, that’s far worse than a botnet taking over my home PC,” said Matthew Carpenter, senior security analyst of InGuardian, speaking at a panel at the RSA Security Conference in San Francisco this week. [ Read more ... ]
Funeral Flap: Justices Weigh Religion, Speech Rights
Funeral Flap: Justices Weigh Religion, Speech Rights: Via Threat Level.
The Supreme Court agreed Monday to delve into the sensitive question of whether the First Amendment protects anti-gay protesters carrying placards outside military funerals saying “America is Doomed,” “Thank God for 9/11″ and other volatile phrases like “Thank God for dead soldiers.”
The messages and picketing are part of a Kansas church’s belief that the United States’ tolerance for homosexuality is cause for soldiers’ deaths in Iraq and Afghanistan.
The case the justices decided to review Monday tests the boundaries of free speech versus freedom of religion — doctrines embodied in the First Amendment.
Without comment, the justices agreed to review last year’s federal appellate decision overturning a $5 million verdict (.pdf) in favor of a Baltimore father who sued the Westboro Baptist Church of Topeka and its pastor, Fred Phelps, in 2006. The father of Marine Lance Cpl. Matthew Snyder was awarded damages for, among other things, invasion of privacy and emotional distress for the events that occurred outside his son’s funeral at a Catholic church in Maryland. [ Read more ... ]
Security Pros Question Deployment of Smart Meters
Security Pros Question Deployment of Smart Meters: Via Threat Level.
The country’s swift deployment of smart-grid technology has security professionals concerned that utilities and smart-meter vendors are repeating the mistakes made in the rollout of the public internet, when security became a priority only after malicious attacks had reached mass levels.
But when it comes to the power grid, the costs of remote hack attacks are potentially more dramatic.
“The cost factor here is what’s turned on its head. We lose control of our grid, that’s far worse than a botnet taking over my home PC,” said Matthew Carpenter, senior security analyst of InGuardian, speaking at a panel at the RSA Security Conference in San Francisco this week. [ Read more ... ]
White House Cyber Czar: ‘There Is No Cyberwar’
White House Cyber Czar: ‘There Is No Cyberwar’: Via Threat Level.
Howard Schmidt, the new cybersecurity czar for the Obama administration, has a short answer for the drumbeat of rhetoric claiming the United States is caught up in a cyberwar that it is losing.
“There is no cyberwar,” Schmidt told Wired.com in a sit-down interview Wednesday at the RSA Security Conference in San Francisco.
“I think that is a terrible metaphor and I think that is a terrible concept,” Schmidt said. “There are no winners in that environment.”
Instead, Schmidt said the government needs to focus its cybersecurity efforts to fight online crime and espionage.
His stance contradicts Michael McConnell, the former director of national intelligence who made headlines last week when he testified to Congress that the country was already in the midst of a cyberwar — and was losing it. [ Read more ... ]
Recent blog posts
- Viacom Makes Its Case Against Yesterday's YouTube
- Obama supports Senators draft plan to rework U.S. immigration policy - Includes National Biometric ID card for all.
- Domain Names Can't Defend Themselves
- Hacker Disables More Than 100 Cars Remotely
- Judges Approves $9.5 Million Facebook ‘Beacon’ Accord
- Hooking Up The Big Brother Machine... And Fighting It
- Court: State Can Dump Non-Sex Offenders Into Registry
- How Privacy Vanishes Online
- Undercover Feds on Social Networking Sites Raise Questions
- FBI Uses Fake Facebook Profiles To Spy On Suspects